CVE-2024-12103

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 24, 2024
CWE ID 639

Summary

CVE-2024-12103 is a newly disclosed vulnerability affecting the Content No Cache plugin for WordPress. The vulnerability, present in all versions up to 0.1.2, exposes information through the eos_dyn_get_content action due to insufficient access restrictions. Unauthenticated attackers can exploit this vulnerability to extract data from password-protected, private, or draft posts, gaining unauthorized access to sensitive information. This issue poses a significant risk to WordPress sites using the Content No Cache plugin and should be addressed promptly by updating to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share